The purpose of this step is to remove the DNSKEY record for the active ZSK from the source signer from the input zone and to resume automated key management. Once this step has taken place, the migration is complete. The situation at the end of this step is shown in the diagram below:

To reach this situation, the following sub-steps need to be taken:

Remove the active ZSK from the source signer from the input zone

If required, update the SOA serial number in your backend system such that it is higher than the SOA serial number that is currently published

Resume automated uploads of the input zone to the destination signer; if you still have zones that are signed and published by the source signer then you can now also resume automated upload of input zones to the source signer

Resume automated key management on the destination signer (in case OpenDNSSEC is used, you can now restart the enforcer component); if you still have zones that are signed and published by the source signer you can also resume automated key management on the source signer